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(54) CIPHER COMMUNICATION METHOD AND SYSTEM 

(57)Abstract: 

PROBLEM TO BE SOLVED: To realize a cipher 
communication system that can continues cipher 
communication even when a decoder is changed due to 
a path change on the occurrence of a path fault during 
the cipher communication. 

SOLUTION: Layout information relating to the layout of 
other routers L12 to L14 capable of cipher 
communication is included in path forming information of 
a router L11 that receives are transmits the path 
information such as a routing protocol. In the case that 
any router such as the router L13 on an optimum path 
during the cipher communication is disabled of 
communication, a new optimum path is formed again 
and continues the cipher communication with the other 
router L14 in existence on the optimum path formed again by using a key decided mutually. 
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[HUB] B»*ii«1>K«lSI»<Fas»4L, 

*Mfc-e * 5 «t*ifli * 7- j» Sr na-f 5 . 

Ifc^ilffiWt&ftft&tfVi'--* L 1 2~L 1 4<£>KEt- 

-ma*©^-*, ffittf^Li sasafflr^tBfcfco 
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[4MMH*©lfiBI] 

t>t, wia^y M7-^±mjstt5aflrt»««Bo*j« io 

*aft Rrtt4a« tfaaaiiB-cfisKBi 9 

Bt-^aft^ifeo 

y h v - * — rsi a» 5 flHHt $ ftfcaft * ©«*fls# 
t?# «»frfc*©aflrii«xtt* y i- y-t (D®stm%k 

*%git*ofct * (^tt^aflTft^meKBUtt « t pi c 20 

k © M T'MW,m<D®. <0 ft ft Srfif 5 r t * t 1- 5 , 

it** 1 eitoit-9aflr^& 

3 ] M£©£^j£11HR*4K*©ai»<f'tt3£ 

«M-eav^2S£iftL*>5 w tiao ss^/Baft t st-si-a 
aisaiw-eaff^--* ©st^affi tfj 5 ^ifv/^f 

#a«*iB8ll©iB»»riiflMRfi. WE*y b!7-^± 30 

■e«f#aflr"Rr«i*aflit«is«oE«fcB8i-5iB«fl!f« 

ffllE«*©aif«£g©'>£< £ fc-ott, Bf^aft 
1'0*ii«*±©afll1'«i»t«©Emii*i6S*JE^*o 
fcrt £«*q Ufc t $ £3K£Xtt©EKfl!rtt*tt©a 
flr«f»S61tta» , 1-5J:5H:«*5n, 4>&<fct>ffi© 
-oil, «TEafeiS:t>i:»cia©ft»»ri£flMll«:3!«fb 

aft»ji#+5ie^flr»r«!ti:aflif*^»iWT?*ii:t 

flt-^-aft wta. 

> tffSi-sftroaffitiMiaatwiRi-citt^-affiSrtTpa 
«f^-afli^riB*aflr ( fttigji©E 

filviM-f-SEglf #Sr^tf t©T"*j 5 , 
W*aflltK:iitfE*afil6KiartSte©fflfll 1 P»Sil© 50 
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* n s utriEieWf fa© rt « * h*-*- « iff t , 
*ffc»-»i*4nfc*aaK±©i«-»afliRni*«i©afli 

att'ttNB&a. 

[»**5l MEfc»»JfcflM*#Br*©A'- 

gnmL£tiz>\nmThr>x, i«M§a«*rfr*.s/-K 

©EWcHi-SflWRW*©/ - K#«f*MrjW©# 
*fc+*aftaK©«WHIH**atrt>©-ei(>9, MEM 

aU«f «fcX-3v ^Tffil5»^S 9 ft ft 5 r J: i 1" 

it*« 4 ia^©am*asfi„ 

[f»*«6] ttEW»Hf«*t>o/-Ki:©Wtf*5 
*ftfc«l*r^ftfiM*LTV^5»&H:-t©«fc*fflU ft 
LTV^v S BE / - K i ©IB £ff 

w#n 5 E*©attiptt£it. 
M#97] swBJE*r#«j4» «f*aflrfjcafli^iB 

t /iofcaW+IBBUJiBB-rSEjMlfWSrWIH-S ± 5 

st*« 4 ia*©am*^^s. 

fcafllf *SS«JcH-*-5E«fllf«*aiiP-t-5 i 5 KMfr 

»*5 4 !Ei£©a«tMg 0 

fcafl t*8llfcH-f5EllflM»Sr«]Ei-5 J: 5 CJEilf 

4 E«©aft +i*^a„ 

H»*9 1 0 ] i$-&affii7Hfeaffi'f'tt3&*:©EBK 
BBi-SEHWaiSr^tfBfSroftKJgjjiflMBSrtirC, K 

Riffl aft t Bt-^-aw k * m mcm^-t z> z. k # x* # 5 * 

amw^sit t ©in t?«F-»am *fi ? mm k > 
mfisait ffi^snwflWWfcMfcfcofcatefce a©s 

B©«flr*^*n5«lEE«ffif«©rt»S:]E*rU, JE 

tfctic r©*ffc<e*aftist£#fiE-f5tt©aflrffi* 

i ©flU-CIR 9 *»fc«tfflv^Tlt^affl*««lEi-5 

««li*3>'tra-^±Ki»J«-t5fcft©7'fi^5A3 

[»W©»»4RW] 

[0001] 
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PMrtttrfcoaflT fiJlTIWi:) tBf-^iiff (Rf^Sffi£ 

a«fc5fe£fctttt-e# a <t 5 tei-5fc»©«F*affitft* 

[0 0 0 2] 

[^dSi] IP (Internet Procotol) *y b7— 10 

*vtv^5„ £©«©flH§-aflr»*, sftftii^Bt^tsiet 

SI) fcJBi*-C*Ttah.S. r.©»fc©affi©»«i:L-C 
r t £ o TrtfWlW £ff 5 ^flg t * h 5 . 

[0 0 0 3] I h !7 — tCdoV , TBS ; -§TS'fSl'ffi V> 

K E (Internet Key Exchange : mHUft^JSR^MIB) ^St 

[0 0 0 4] bZZ>X\ IP^^hP-^OTLTi 

flrfcfTo-cv^Sftt^iaiiBUS^fei*©!*****^ 

fcS^li, O S P F (Open ShortestPath First) 
(0;P-t^ y^T'n h a/W^ftl Lfe 9 > A'— *3e©S 

fli t fi«iijii#©»o^y^ry7'a«nas««*«ffl 30 

Lfc9L-taflr*@«Stf«£i:#-e#<5. g 

5 0 «T, ^H6©«fllEI«*ife©«5SrlllWi-5. 
[0 0 0 5] (l)A^T^^nF^ftfflW: 

0 6i^-r i 5 awseT 1 1 tatt^ei 2 t© 

M©I P^y M7-^±©y-Kl-^-^N 1 1~N1 

5*ssstts*iTv^5i:-t-*«. 3EHfi*©*aaa6it, aft 

IggT 1 H/P-!?N1 H^-?N1 2-»;l^^Nl 
3->/l'— ^ N 1 5— HSHaSffiT 1 2 , *>5VM4^©iS*t? 40 
fo«K ^-?N1 1~N 1 511 SLW-WPoTl^ig 
KJBj*W*U rftfrt^-^ttgeif©^-* iififB 

[0 0 0 6] r©ftiI&8£*5I^T, A— ;?N13(C|S| 
*#3&±Lfc»£H:, &T©£ 5fcWeaff©(Bl«S: 

xtf/i"-^Ni 2 as, /u-^jyyyu v^jwmanz 
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TV^ 0 WE^Sr^L^u-^N 1 211, r3-$-e©& 

9, P^1"?)^-^N 1 1 , N14l'a*P-t5o 
©afctiWRtt, SfflSi-S-'U-^N 1 5fCt>!> 

SftjS-t"^— 90)9)^— -f) ©-f-^-c©^— ^(^a*P§ 
tb5. i©J:5li«U<a*P*ix5fll«fcJ:!)» 
*N11, N12, N14, N 1 5 tftt*3&tt$j£1IMR 

ttjewsfu p«M8»©ft*>9ic*5aiattK» ■*-**> 

*>, aftSIST 1 l-»^-?Nl H/V-^N1 2-M' 
— *N 1 4-»;U-?Nl 5->afti£ttT 1 2©&gg;SSi? 

[000 7] (2) '<y*Ty7SBR*a««:«SL 

n i 2 #«t»iNt®&fcl»*:W8±L;fc:r. t Lfca-g- 

*) VfciB) , WN1 2f±» ^y^TyT'ftlMl 
JHi»c3t-3v^-c, ^fcRfcLTfevferaMW 
9Ty?Wto fcflDD#*.Taflr«:*o. 
[0 0 0 8] 

[*Mi**BfcUJ: 5 t LTV^S&g] aftaffi©^ftfc 
Lfc#&t>» ±IE©/1— y-f h=nA/©««&^< 

L*»Lfrtfsp>, sif-^aft©#-g-n ^-r 

^ V^7"n b3^©«|ffi$)5Vfi^s'^Ts'^'gte^© 
ft, R#©tttt*©**-Cf±» HWfcSllfclP^? 

[0 0 0 9] riT'tt, HI 7 t^i"flfjS, i"*fc*>, 
N 1 2 tCBt^SM 2 1 4r^- LTafsggT 1 1 AS 
SN**H, ^~ ?N1 5[caif^gT2 2iJ«NSt**u, 
$ ?N 1 2 iy^Nl 5 i©Ffltc, iti^ti 

«tfglM2 2, M2 3as^lJl^igc$ixfc I P^y h 

[0010] #;l/-?N12, N 1 5 StMf-iHSISM 2 
1, M2 2I4, ^V^|t*So■rv^5»K^RJ«^(r««:S«U 
M\ *y H7-^IH©*aaB*»fi!lU-CV^5 0 
R*lc*stt5*a»R» o*9a»8KT««|CUfc»fr© 
SBfl, affl^ETl l-»«t#8*MS H^Nl 
2 -^Blf-^gffiM 2 2 ^ N 1 5 -^afSSST 1 2f 

as^-seM2iji, affi^gT 2 2a^j^t $n 

eSg*fcflf-W£EM2 2t©M-?fflv^ 
(W*tf#A) 4rfflv^Tflf*<lsi-4. 
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[0 0 1 1 ] rco^ffiT, flf-*H£gM2 2T{5If>rf)M£>|i$ 
2 1^-^N1 2-*ff|p-tgeM2 3^-?Nl 5-» 

aflrssiiT i 2KSttttt*jEsnfcii-s. ^©m 

3\ **S6jlM2 1 t«F*SfijtM2 3i©Wt»fflV^f>Jx 
5 0 La>U WF*S«M2 lTftt, h©S*flS3fc 

(am^STi 2) fcjEjEtffc^o-e, «i»iti 1 

*»biifSS?ttT 1 2&fci^£ft5xW©ll|f-f§7B«$: 10 
a A B fcfcJE-*-^* T*& 5 r k *®Jk<r>iV-7- 4 

bttl**§MM2 nMBA-CflHS-flsSih, 
Sritc/ilK »B£ffl^.5Rf-)§-i£BM2 3-C|-±rix£ 

[0 0 12] HF#aWKH\ atff£©T KU*£^trI 
P ^ y ? t **r v V ©x-*&# (■*-**> 

©T Kl^Sr^tf I P^s^SrttLTaffi&ff 5 hi'* 20 
2 2 Lfc t # Id, Rg-i^BM 2 1 Ttti© 

[0013] z.<n>&bti3§mt, ^mm^mmmm 

if ic ffl v ft 5 H t B 36 W T* *> o fc i £ legal" 5 . 
[0 0 14] ^it*^^ iffjnTJBSff £Rf^afii: 

«#flsfcfr 5 3l«©E**Jfcfc«1E#£ tfc^-efco 
Tt>, l«*ffi©itfclbf&fc*KLTI*#a««r££tatt 

■f-5. 
[0 0 1 5] 

[Rja&tffti-5fc»©*«l ±lEHMISr#ftfc«>s * 40 

[0 0 16] *5SW©«F*afll*ifeH:, ift-sifflaffiirBt 
*afti*HB*fc£9W-5 5* y h7*-*£ 

^-LTtT?*fe-C-fco-C, 4iy M7-^±T?lflF-»afl|Br 

Bg^aff^«^B©ffitttii-5ia*ttis^tffiff^© 
iKisjKriiitssrttsoaf&taagaiBTEv^i^iftLfc 

t, ^©*aii»n:#s-f-5a{s^itt«*wn?a«'r- 50 
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»t 5 aft * WkWfiM&lMaL $ t WWEIUB 

rittt**Xtf LT*fcWMiRtt*S#iaiU Sprite 

*ifc*att(SK#-t s tf-s-aft w«*aflr«p»«BM-c 

biwmti-z, ^m^mmmit, hzmmmx\* 
i 5 ■? * 5 »£- k * ©aft igBxtt* y h y - 9 <omm 

«4rB*Lf*J*. ft©aft*itt8Bfi>b&lHgj*flNl 

igim-o it t § icR»^a«ft^ttGwwtt« t n ess 
9H»«ft««fur^fc»frt, ffrettoaflr-fHiiteCj: 

[0 0 17] *^PjroBt#aftv'^7 1 i>.li, 0f^wS*& 
t i 9 ift^Ifflaffi t *-&ait t *rw*cnai-5 - 1 

-^•amtrff 5Bt#affi->^ri»,T-fe5 0 «-affif«^fi 

*aflT«flK6«oi!«KHi-5E*nif««r^tft>0-C*> 

9, a»©aflrt>«3i6ji©*4<i:t-oi±, s&^aft 
«t>©*ai«i»±©aflrf«iiE«©E«»*#*jEicfto 

fcii Lfc t * (cSttXX«©EMIlF*«:4ii©a 

«t>idai«Ka*p-f5 i 5 t ttt© 

-oli, Mneafti«:t>2:(z:iB©ilK»i£tlNR«:3C*rb 
■C*ffc**aft»*S»J«-f-5 * fc t K?¥»**Jxfc» 

*0*»fc«ftfflv^WE*#aflrS:*IR1-SJ:5K^* 

[0 0 18] *^P^©aftt»ilSKs @f*©S?&^fi!<; 
If S: t> 1 y h !7 - ^ ±t*s It 5 affix- * ©ft^ 
5 1 1 % fc r ©ftiiS!^lc#Si--5m©a 

ft ^^se t ©^-eBt^-atssrfi 1 5 a^S4 J »sg^43^^ 

©E«tH1-5E»fll**r*bt>©T?*>5^ H&^-affi* 

tafliffi^i: ftsft©a«f «as«i*afli3f:iBfc*ofc 

i:*^SB©il6B»j*flHlllc^*ix*mBE«»«©rt 

»B±©Bt*afliwtB4«i©aflrtt'«ss»sr*w-}-s^ 
st^ffi^^ ssttwufcaflrttfa^twiii-esi^ft 

*/ca2rfflV^TB|f-§-affi r t ZftWlbi-Z>m 
Bt?fc5. 

[0019] g|gjg/£ff ««:, ± 5 Jlfr(ft»CH0fJ&©^ 
-f^y^o b=/Ht*-3v^Ttt©ait«f«ISBi© 

x.5 / - K©EBt-M-t5if ^^©y - K#pf *l 
(t^lfcwitfctl-saflrSBroWBiJflrtRSr^tft©^*) 

«»Jttf«*t>o>'-Ki©IH]-eiR5*ftfc*«r ; J i ' 
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ftfiM*LTV*5#£tt:-t©**S|iliiU «*{W*L-0* 

[0020] aflr«f«as*ic48rt4M«f¥att, whhi 
ft * taflmi tfto fcaflrf *»« a* s> s*&i4-t*i 

fcH1-5E«***fiiJBftU Bt^-iift+^iSe^H/cii 

[0 0 2 1] ;M&H#ttlt-*-3Efttt#r^ Bf-^affi^I 10 
*fca«**§M©E«fcH1-«EWim«r£&Br:e© 

B©a^*ttNiifc^*H*iWEE«flMR©rt* 

fl&©ilff ffi^gg t WF^T-Sc 5 flW>fc**:ffl^-Clfr*a 
[0 0 2 2] 

[*«©**©»*] BT, HB5*r#BRLr*3BWo3S 
i^:/n h=*|cf£oTfci^jM**©S6tt«L«rfT3 

snii]-c*«afli*rfforv^»^-fc, Bfr&awasRrtB 

ft^it ©Eg fc Mi- 5 Ifftt Sr-LEffl&flMM* * , 

J;5tci-5o 0!lx»4\ y -ytxT— h^co/p-x-o^ 
ha/uffcjxii, if© y K:it#aflrsriB4ISfi 

^BEg£:ft/c^T£:*;i©^y hy-^WT-Rt-^affi 
;t5©;S\ f^^y^^ Wkit©^— • r-< i/#-fv 

{fcr-*£i£{t1-5|gtc:, 3Mt$fc©iff^11fc*tj£Lfc 

[oo23] ±^»nt^-a{t*fe(4, witfBi i i-^-r 
^±KE$iifcasflr«©aflr8»Ti i, 

^±Cia$tifcSefll©Mgf t l 2, rixibcojlff 

ssmw^fci-sfc*©^*, -t-Jifc-ibA^-^ l i 

1, D^-ni2, B;^L13, L 1 4 

*afti*H«#CS5a-?#S±5fc#J5£*ft5. 50 
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£$a^f ffi Sr^ L Tjgigg $ ftT V n 5 fc © i "f 5. 
[0 0 2 4] #WL1 1~L 1 4f4, feVRVC 

P FaA'Ottt, MF#a<I©ttkfe XV. i*L&©«|6 

Ht c p u#k* t o -sstet&mw* * y ^©b^mis® 
flt#"ca>5#» cD-ROM*©Brw£E*Mfl*at 

tM6fco^T»i» fB*©A~-*©t>©&£*ftfcH:ni; 

-es>5#, /W-x^ V^p h=^^&©^— 

(1) «f*iflr4rffjL5y-K (/V-*) OEW"fy 

i d 

(2) t©y-Kas#*afli«ft©«*ii-5aflWHi 

I D 

09: rA/p-*Kj3rt5flf-*a«©#ft (aflMBSi 

d) w\ vy—tR-a-y^-v M7-^©iifi^*t 

rtibroifs^mi-^x-^©^*, aisi-s*y 

fcfc©tcfc5 0 #lx_(4* I P^y F 17 — # ©O S P F©^§ 
#(4, ^Sfi-fSLSA (Link State Advertisement) 
■t©ttf#*^«)5r tK45. 
[0 0 2 5] HF*afll ©*IBfcHL-C % * 
(4, 6tT©J;5fcL-Clff*afll«:fl5. 

( 1 ) i**affi%ifesttfc©aflr&ft i d c^tsm 

0!) : rA;u— ^Sraii'tS^^y h©y— KW*5 
*y M7-^t*+5^y M4, °f4 7>?4*— 

s/ayrKv^asafliftKiDta^-rs©^, hhhs 

(2) Hf*ffl©ntt, aflrais^jci-aaflMHS i d 

^KFofcy- K©t©?ri ! 'i6^LTV>^^-g-{4^?r 
1-5. 

W : ^K)^—9t^ H7-^^©Sgg±(C, B/U 
-#tV^5lit*a^Wl6!ic-'V^-4'^#iEU ^©B;u 
-*iSfl*yH7-^K# LTBf -^-iiff *J5fe©*t* t L 
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[0 0 2 6] ft*5, «±^aWBtt. £tcd;u-^ L l l 
~Li4^lx.tv^rt^aiu^, I*8iTl 

[0027] m^, ^%wrM<D^mt^^y-^i\z 

*y h!7-^F*3tf>iiffi^HT 1 1 tA;^?L 1 1 MO 
*y M7-*T K^*;&S T163. 135. 10.0/24J s 

vy—ppwm^&WT i 2tB/u^L i 3xac;v 

— 1 4 t<F>m<D-< >97^ — XT KU*j&S r 163. 13 
5.20.0/24J , A;^L1 l©-f y?7x^7Kl/ 
F163. 135. 100. 10J , Bj^—9L 1 3<D-f 1/9 y*. 
-^7K^^ T163. 135.200.20J , C/^^L140 
*yH7^-?7KWiS ri63. 135.300.30J 

^fcSiiaosPF^acASrtToTBf-^iiftSrfif?** 20 
<£>0J«r*tf5o O S P FMoV^T{4> H»«BBIETFT38 
fTLTV^5ttfi|RFC2328, RFC113U STD0054KpjHH»CSB 

[0 0 2 8] OSPF-Cttffi*ix5aB»fiRfl!f«, 1"ft 
t>h x ) V^^KRjE^^ry h (L S A : Link State Adv 
ertisement) 9 L 1 1~L 1 4 ^ff-f 

rco/U-^y :/^LSAf4. WR/U-^WCgltaEStt 

£ ixsttf #m i ot#;w-# asftfe(7)yp-^ coiasi-Hi- 

LfcfcOT*5. ^7*1-414, K^<0/u-9»MM 

oT^5*>S;;ba>5£5l--*"So ^^^5Cfe^T, y 40 
^7-^jSNu 1 1 *&Tfc££;h/T^ft^ 

[0 0 2 9] LSAft £/l~^L 11-L1 4tSt 
5y^flm*r*«»flM-5ri:iS^t5o «oT, - 

nf4\ Bt*aflrfflLSAfc**»*"c#5o fli*.tf. * 
-f^sc^Ls A-ey i Difi ri63. 135. ioo. ioj , y 

>9y**-9i!fi Ti63. 135. 20. 0/24J ffofttf, rcOLS 
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* NOTICES * 

JPO and NCIPI are not responsible for any 
damages caused by the use of this translation. 

1 This document has been translated by computer. So the translation may not reflect the original 
precisely. 

2.**** shows the word which can not be translated. 
3. In the drawings, any words are not translated. 



CLAIMS 



(57) [Claim(s)] 
[Claim 1] 

It is the cryptocommunication approach of performing communication link for Takayoshi, and 
cryptocommunication through a network realizable to coincidence, 

The optimal path on a network is formed by exchanging mutually predetennined path formation 
information including the arrangement information about arrangement of the communication link 
repeating installation in which cryptocommunication is possible among two or more communication 
link repeating installation, and suiting on said network. While performing cryptocommunication of 
commo data between the communication link repeating installation which exists in this optimal path 
When the configuration of the communication link repeating installation on said network is changed, 
said path formation information is updated and it is characterized by continuing said 
cryptocommunication using the key fixed mutually between the communication link repeating 
installation which carries out the reconstititution of the new optimal path, and consists in the optimal 
path by which the reconstititution was carried out and in which cryptocommunication is possible, 
The cryptocommunication approach. 
[Claim 2] 

Each communication link repeating installation records the identification information of the 
communication device or a network, when a decryption of the enciphered commo data which goes to a 
certain communication device or network can be performed, and when said path formation information 
is received from other communication link repeating installation and the cryptocommunication point 
holds the same identification information as said identification information, it is characterized by settling 
on said key between communication link repeating installation besides the above, 
The cryptocommunication approach according to claim 1. 
[Claim 3] 

It is the cryptocommunication system which performs cryptocommunication of commo data between the 
communication link repeating installation which forms the optimal path on the network which can 
realize communication link for Takayoshi, and cryptocommunication to coincidence, and exists in this 
optimal path by exchanging predetermined path formation information mutually among two or more 
communication link repeating installation, and suiting, 

The path formation information on each communication link repeating installation includes the 
arrangement information about arrangement of the communication link repeating installation in which 
cryptocommunication is possible on said network, 

At least one of said two or more of the communication link repeating installation It is constituted so that 
the arrangement information after the modification concerned may be notified to other communication 
link repeating installation, when it detects that the arrangement configuration of the communication link 
repeating installation on the optimal path under cryptocommunication w*as changed. Other one [ at 
least ] While updating the path formation information on self based on said notice and carrying out the 
reconstititution of the new optimal path to it, it is characterized by being constituted so that said 
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cryptocommunication may be continued using the key fixed mutually between the communication link 
repeating installation which consists in the optimal path by which the reconstititution was carried out 
and in which cryptocommunication is possible, 
Cryptocommunication system. 
[Claim 4] 

While forming the optimal path on the network which can realize communication link for Takayoshi, 

and cryptocommunication to coincidence based on predetermined path formation information, it is the 

communication link repeating installation which performs cryptocommunication among other 

communication link repeating installation which exists in this optimal path, 

Said path formation information includes the arrangement information about arrangement of the 

communication link repeating installation in which cryptocommunication is possible, 

An updating means to update the contents of said arrangement information included in the path 

formation information on self when the arrangement configuration of other communication link 

repeating installation in said optimal path is changed during cryptocommunication, 

Path means forming which forms a new optimal path based on the path formation information after 

updating, 

It has a detection means to detect other communication link repeating installation in which the 
cryptocommunication on the newly formed optimal path is possible, 

It is characterized by continuing cryptocommunication using the key fixed between the detected 
communication link repeating installation concerned, 
Communication link repeating installation. 
[Claim 5] 

it is the information by which said path formation information is mutually delivered and carried out 
among other communication link repeating installation based on a predetermined routing protocol, and 
the information about arrangement of the node which can perform cryptocommunication, and its node 
are characterized by fixing said key based on said identification information including the identification 
information of the communication path made into the object of cryptocommunication implementation 
Communication link repeating installation according to claim 4. 
[Claim 6] 

When the key fixed between nodes with said identification information is held beforehand, the key is 
****(ed), and when the key is not held, it is characterized by securing said key by performing key 
generation between the nodes concerned, 

Communication link repeating installation according to claim 5. 
[Claim 7] 

It is characterized by updating said updating means so that the arrangement information about the 
communication link repeating installation used as communication link impossible may be deleted during 
cryptocommunication, 

Communication link repeating installation according to claim 4. 
[Claim 8] 

It is characterized by updating said updating means so that the arrangement information about the 
communication link repeating installation extended during cryptocommunication may be added, 
Communication link repeating installation according to claim 4. 
[Claim 9] 

It is characterized by updating said updating means so that the arrangement information about the 
communication link repeating installation moved during cryptocommunication may be corrected, 
Communication link repeating installation according to claim 4. 
[Claim 10] 

The function which forms the optimal path on the network network which can realize communication 
link for Takayoshi, and cryptocommunication to coincidence based on predetermined path formation 
information including the arrangement information about arrangement of the communication link 
repeating installation in which cryptocommunication is possible, 
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The function to perform cryptocommunication between communications-partner equipment, 
The record medium with which the program code for forming on a computer the function which 
continues cryptocommunication using the key which fixed among other communications-partner 
equipments which exist in this new optimal path while update the contents of said arrangement 
information included in the path formation information on self and forming a new optimal path based on 
the path formation information after updating, when the configuration of said communications-partner 
equipment is changed was recorded and in which a computer readout is possible. 

[Translation done.] 
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* NOTICES * 

JPO and NCI PI are not responsible for any 
damages caused by the use of this translation. 

1. This document has been translated by computer. So the translation may not reflect the original 
precisely. 

2. **** shows the word which can not be translated. 
3. In the drawings, any words are not translated. 

TECHNICAL FIELD 
[Field of the Invention] 

Modification of the configuration of communication link repeating installation arises during 
cryptocommunication, and even if this invention is the case where an optimal path changes, it relates to 
the cryptocommunication technique for continuing cryptocommunication safely in the network which 
the communication link for Takayoshi (it is the same the communication link which has the 
communication link in which the automatic continuation by path change is possible, i.e., failure-proof 
nature, also in the time of a failure, and the following), and cryptocommunication (it is the same the 
secret communication link using a code technique and the following) can realize to coincidence. 
[0002] 

[Translation done.] 
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PRIOR ART 



[Description of the Prior Art] 

The gestalt of the cryptocommunication performed using IP (Internet Procotol) network is known better 
than before. This kind of cryptocommunication is performed using the key (a cryptographic key / decode 
key) generated between the encryption equipment of a transmitting side, and the decryption equipment 
of a receiving side. As a gestalt of the communication link in this case, there are a gestalt which 
performs cryptocommunication by end to end, and a gestalt which performs cryptocommunication by 
arranging the communication device (following, "data encryption equipment") which performs 
encryption and a decryption of commo data, for example, a packet, on a communication path. 
[0003] 

As a procedure of generation of the key used for cryptocommunication in IP network, key exchange, and 
a key setup, various technique, such as an IKE (Internet Key Exchange: cryptographic key generation 
procedure) method, exists, for example. A transmitting side enciphers an IP packet using this generated 
key (cryptographic key), and a receiving side decrypts a packet using the key (decode key) 
corresponding to this key. 
[0004] 

By the way, when a certain failure occurs at an optimal path in the midst which is communicating using 
IP network, a communication link can be recovered, and using the backup routing function which the 
communication link repeating installation itself, such as a router, has. [ using routing protocols such as 
OSPF (Open ShortestPath First), ] That is, an alternate route can be set up automatically and a 
communication link can be recovered. Hereafter, the outline of these communication link methods of 
recovery is explained. 
[0005] 

(1) When a routing protocol is used 

As shown in drawing 6 , suppose that routers Nl 1-N15 are connected to the node on IP network 
between a communication device Tl 1 and a communication device 12. The optimal path of forward 
always exchanges mutually the information [ information /, i.e., express which router and 
communication link are directly possible for each router, / the communication device Tl 1 -> router Nil 
-> router N12 -> router N13 -> router N15 -> communication device T12 or its path formation 
information / information / which is reverse and has mutually each routers Nl 1-N15 ], and forms the 
optimal path between networks. 
[0006] 

In this optimal path, when a failure occurs in a router N 13, the following procedures recover a 
communication link. 

First, the normal router N12 which carries out proximal to a router N 13, for example, a router, detects 
that the failure occurred in the router N13 by the function of a routing protocol. The detection approach 
is determined by the routing protocol. The router N12 which' detected the failure notifies information, 
such as "an old path was not able to be used" or "the link having been lost", to the adjoining routers Nil 
and N14 by the function of a routing protocol. Such notice information is relayed also to the adjoining 
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router N 15, and, thereby, is notified to all the routers of a routing domain (group of a router who 
delivers routing information). Thus, the path formation information which each routers Nl 1, N12, N14, 
and'N 15 have is updated by the information notified newly, and the reconstititution of the alternate route 
which becomes instead of a failure path, i.e., the path of the communication device Tl 1 -> router Nl 1 -> 
router N12 -> router N14 -> router N15 -> communication device T12, is carried out. 
[0007] 

(2) When a backup routing function is used 

A backup routing function is in a certain router N12 in the communication system shown in drawing 6 , 
for example, a router, the case (polling (supervisory signal) the existence of a link --) where a router N12 
detects that the failure occurred for the junction path it is based on keep alive (signal for confirming that 
the circuit is not downed) etc. ~ a router N12 is changed to the alternate route (backup path) set up 
beforehand based on a backup routing function, and maintains a communication link. 
[0008] 



[Translation done.] 
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EFFECT OF THE INVENTION 



[Effect of the Invention] 

Even if it is the case where modification arises to the equipment to decrypt, i.e., a key, as a result of 
making a path change during cryptocommunication according to this invention so that clearly from the 
above explanation, there are insurance and characteristic effectiveness [ say / that it can continue now 
certainly ] about cryptocommunication. 
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DETAILED DESCRIPTION 



[Detailed Description of the Invention] 
[0001] 

[Field of the Invention] 

Modification of the configuration of communication link repeating installation arises during 
cryptocommunication, and even if this invention is the case where an optimal path changes, it relates to 
the cryptocommunication technique for continuing cryptocommunication safely in the network which 
the communication link for Takayoshi (it is the same the communication link which has the 
communication link in which the automatic continuation by path change is possible, i.e., failure-proof 
nature, also in the time of a failure, and the following), and cryptocommunication (it is the same the 
secret communication link using a code technique and the following) can realize to coincidence. 
[0002] 

[Description of the Prior Art] 

The gestalt of the cryptocommunication performed using IP (Internet Procotol) network is known better 
than before. This kind of cryptocommunication is performed using the key (a cryptographic key / decode 
key) generated between the encryption equipment of a transmitting side, and the decryption equipment 
of a receiving side. As a gestalt of the communication link in this case, there are a gestalt which 
performs cryptocommunication by end to end, and a gestalt which performs cryptocommunication by 
arranging the communication device (following, "data encryption equipment") which performs 
encryption and a decryption of commo data, for example, a packet, on a communication path. 
[0003] 

As a procedure of generation of the key used for cryptocommunication in IP network, key exchange, and 
a key setup, various technique, such as an IKE (Internet Key Exchange: cryptographic key generation 
procedure) method, exists, for example. A transmitting side enciphers an IP packet using this generated 
key (cryptographic key), and a receiving side decrypts a packet using the key (decode key) 
corresponding to this key. 
[0004] 

By the way, when a certain failure occurs at an optimal path in the midst which is communicating using 
IP network, a communication link can be recovered, and using the backup routing function which the 
communication link repeating installation itself, such as a router, has. [ using routing protocols such as 
OSPF (Open ShortestPath First), ] That is, an alternate route can be set up automatically and a 
communication link can be recovered. Hereafter, the outline of these communication link methods of 
recovery is explained. 
[0005] 

(1) When a routing protocol is used 

As shown in drawing 6 , suppose that routers N11-N15 are connected to the node on IP network 
between a communication device Til and a communication device 12. The optimal path of forward ' 
always exchanges mutually the information [ information /, i.e., express which router and 
communication link are directly possible for each router, / the communication device Tl 1 -> router Nil 



http://www4.ipdLncipi.go.jp/cgi-bin/tran_web_cgi_ejje 



10/25/2006 



JP,3821990,B [DETAILED DESCRIPTION] 



Page 2 of 8 



-> router N12 -> router N13 -> router N15 -> communication device T12 or its path formation 
information / information / which is reverse and has mutually each routers Nl 1-N15 ], and forms the 
optimal path between networks. 
[0006] 

In this optimal path, when a failure occurs in a router N 13, the following procedures recover a 
communication link. 

First, the normal router N12 which carries out proximal to a router N 13, for example, a router, detects 
that the failure occurred in the router N13 by the function of a routing protocol. The detection approach 
is determined by the routing protocol. The router N 12 which detected the failure notifies information, 
such as "an old path was not able to be used" or "the link having been lost", to the adjoining routers Nil 
and N14 by the function of a routing protocol. Such notice information is relayed also to the adjoining 
router N 15, and, thereby, is notified to all the routers of a routing domain (group of a router who 
delivers routing information). Thus, the path formation information which each routers Nil, N12, N14, 
and N15 have is updated by the information notified newly, and the reconstititution of the alternate route 
which becomes instead of a failure path, i.e., the path of the communication device Tl 1 -> router Nl 1 -> 
router N12 -> router N14 -> router N15 -> communication device T12, is carried out. 
[0007] 

(2) When a backup routing function is used 

A backup routing function is in a certain router N12 in the communication system shown in drawing 6 , 
for example, a router, the case (polling (supervisory signal) the existence of a link — ) where a router N12 
detects that the failure occurred for the junction path it is based on keep alive (signal for confirming that 
the circuit is not downed) etc. — a router N12 is changed to the alternate route (backup path) set up 
beforehand based on a backup routing function, and maintains a communication link. 
[0008] 

[Problem(s) to be Solved by the Invention] 

Usually, also when a failure occurs in an optimal path, an alternate route can be formed in the midst 
which is performing not only a communication link but cryptocommunication using the above- 
mentioned function and above-mentioned backup routing function of a routing protocol. However, since 
the function of a routing protocol or the change function to a backup path, and the function of 
cryptocommunication have another composition, with the existing structure, in the case of 
cryptocommunication, the enciphered BP packet (encryption data) cannot be decrypted, and it may be 
unable to continue cryptocommunication. This is explained below. 
[0009] 

Here, a communication device Tl 1 is connected to the configuration N12 shown in drawing 7 , i.e., a 
router, through data encryption equipment M21, a communication device T22 is connected to a router 
N15, and IP network configuration by which data encryption equipment M22 and M23 was connected to 
juxtaposition between the router N12 and the router N15, respectively is assumed further. 
[0010] 

Each routers N12 and N15 and data encryption equipment M21 and M22 exchange the path formation 
information which it has mutually, suit, and form the optimal path between networks. The optimal path 
in always [ forward ], i.e., the path at the time of usually converging in a path, is the communication 
device Tl 1 -> data-encryption-equipment M21 -> router N12 -> data-encryption-equipment M22 -> 
router N15 -> communication device T12, and data encryption equipment M21 enciphers the packet 
transmitted from a communication device T22 using the key (for example, the key A) used between self- 
equipment and data encryption equipment M22. 
[0011] 

Suppose that a certain failure occurred with data encryption equipment M22, a path change was made by 
the function of a routing protocol, and the optimal path was automatically changed into the v 
communication device Til -> data-encryption-equipment M21 -> router N12 -> data-encryption- 
equipment M23 -> router N15 -> communication device T12 in this condition. In this case, the key (for 
example, the key B) used between data encryption equipment M21 and data encryption equipment M23 
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differs from the key A mentioned above. However, in data encryption equipment M21, since there is no 
modification in the transmission place (communication device T12) of a packet, from the conventional 
routing protocol, it cannot recognize that the key for codes of the data transmitted to a communication 
device T12 from a communication device Tl 1 should be changed into Key B from Key A. Therefore, 
since it will be enciphered with Key A with data encryption equipment M21 and the packet concerned 
cannot decode this in the data encryption equipment M23 using Key B, cryptocommunication is 
unrecoverable after all. 
[0012] 

The tunnel mode which enciphers collectively a part for the data division of IP header which includes 
the address of a transmission place in cryptocommunication, and a packet (namely, payload), and 
communicates by attaching IP header including the address of a new transmission place (decryption 
equipment), Although the transmission place address has the transport mode which does not encipher 
but enciphers only a part for the data division of a packet, when a failure occurs with data encryption 
equipment M22 as mentioned above, with data encryption equipment M21, the need for modification of 
a key can be recognized in neither of the modes. 
[0013] 

Such a problem is produced in common, the case where a router, data encryption equipment, a 
communication device, etc. are newly extended by the part (node) which was an optimal path till then, 
when the parts of a router etc. move, and not only when a path failure occurs during 
cryptocommunication but when. It originates in having been [ this ] fixed, and the key used for 
cryptocommunication having been fixed. [ of arrangement of the router in this conventional kind of 
communication link for Takayoshi etc. ] 
[0014] 

Then, even if this invention is the case where modification arises in the arrangement configuration of the 
equipment with which the communication link for Takayoshi and cryptocommunication perform 
encryption and a decryption in a network realizable to coincidence, it makes it a main technical problem 
to offer the technique which changes the key for codes dynamically and enables it to continue 
cryptocommunication safely. 
[0015] 

[Means for Solving the Problem] 

The record medium which becomes suitable when a computer realizes the cryptocommunication 
approach by which this invention was improved in the above-mentioned technical problem for the 
solution reason, a cryptocommunication system, communication link repeating installation, and 
communication link repeating installation is offered. 
[0016] 

The cryptocommunication approach of this invention is an approach of performing communication link 
for Takayoshi, and cryptocommunication through a network realizable to coincidence. The optimal path 
on a network is formed by exchanging mutually predetermined path formation information including the 
arrangement information about arrangement of the communication link repeating installation in which 
cryptocommunication is possible among two or more communication link repeating installation, and 
suiting on a network. While performing cryptocommunication of commo data between the 
communication link repeating installation which exists in this optimal path It is characterized by 
continuing said cryptocommunication using the key fixed mutually between the communication link 
repeating installation which updates said path formation information, carries out the reconstititution of 
the new optimal path when the configuration of the communication link repeating installation on said 
network is changed, and consists in the optimal path by which the reconstititution was carried out and in 
which cryptocommunication is possible. Each communication link repeating installation records the 
identification information of the communication device or a network, when a decryption cjf the 
enciphered commo data which goes to a certain communication device or network can be performed, 
and when path formation information is received from other communication link repeating installation 
and the cryptocommunication point holds the same identification information as said identification 
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information, it is made to settle between communication link repeating installation besides the above on 
a key. 

[0017] / 

The cryptocommunication system of this invention is a cryptocommunication system which performs 
cryptocommunication of commo data between the communication link repeating installation which 
forms the optimal path on the network which can realize communication link for Takayoshi, and 
cryptocommunication to coincidence, and exists in this optimal path by exchanging predetermined path 
formation information mutually among two or more communication link repeating installation, and 
suiting. The path formation information on each communication link repeating installation is what 
includes the arrangement information about arrangement of the communication link repeating 
installation in which cryptocommunication is possible on said network. At least one of two or more of 
the communication link repeating installation It is constituted so that the arrangement information after 
the modification concerned may be notified to other communication link repeating installation, when it 
detects that the arrangement configuration of the communication link repeating installation on the 
optimal path under cryptocommunication was changed. Other one [ at least ] While updating the path 
formation information on self based on said notice and carrying out the reconstititution of the new 
optimal path to it, it is characterized by being constituted so that said cryptocommunication may be 
continued using the key fixed mutually between the communication link repeating installation which 
consists in the optimal path by which the reconstititution was carried out and in which 
cryptocommunication is possible. 
[0018] 

In the communication link repeating installation which performs cryptocommunication among other 
communication link repeating installation which exists in this optimal path while the communication 
link repeating installation of this invention forms the optimal path of the commo data on a network 
based on predetermined path formation information Said path formation information is a thing including 
the arrangement information about arrangement of the communication link repeating installation in 
which cryptocommunication is possible. A means to update the contents of said arrangement 
information included in the path formation information on self when other communication link repeating 
installation which serves as a communications partner during cryptocommunication becomes 
communication link impossible, It is equipment characterized by continuing cryptocommunication using 
the key which was equipped with a means to form a new optimal path based on the path formation 
information after updating, and a means to detect other communication link repeating installation in 
which the cryptocommunication on the newly formed optimal path is possible, and was fixed between 
the detected communication link repeating installation concerned. 
[0019] 

it is the information more specifically mutually delivered and carried out among other communication 
link repeating installation based on a predetermined routing protocol, and, as for path formation 
information, the information about arrangement of the node which can perform cryptocommunication, 
and its node fix said key based on this identification information including the identification information 
of the communication path made into the object of cryptocommunication implementation. When the key 
fixed between nodes with identification information is held beforehand, the key is ****(ed), and when 
the key is not held, said key is secured by performing key generation between the nodes concerned. 
[0020] 

The updating means in communication link repeating installation deletes the arrangement information 
about it, when the communication link repeating installation used as communication link impossible is 
during cryptocommunication, when there is communication link repeating installation extended during 
cryptocommunication, it adds the arrangement information about it, and when there is communication 
link repeating installation moved during cryptocommunication, it corrects the arrangement information 
about it. 
[0021] 

The record medium which this invention offers based on predetermined path formation information 
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including the arrangement information about arrangement of the communication link repeating 
installation in which cryptocommunication is possible The function which forms the optimal path on the 
network which can realize communication link for Takayoshi, and cryptocommunication to coincidence, 
When the function to perform cryptocommunication between communications-partner equipment, and 
the configuration of said communications-partner equipment are changed, while updating the contents of 
said arrangement information included in the path formation information on self and forming a new 
optimal path based on the path formation information after updating It is the record medium with which 
the program code for forming on a computer the function which continues cryptocommunication using 
the key fixed among other communications-partner equipments which exist in this new optimal path was 
recorded and in which a computer readout is possible. 
[0022] 

[Embodiment of the Invention] 

Hereafter, the operation gestalt of this invention is explained with reference to a drawing. 
When the communication link for Takayoshi and cryptocommunication are performing 
cryptocommunication between the equipment which delivers path formation information in a network 
realizable to coincidence according to a routing protocol, the information about arrangement of the 
equipment in which cryptocommunication is possible is included in the above-mentioned path formation 
information, and it is made to make path formation information and the information about modification 
of a key link in this invention. 

For example, if it is the routing protocol of the De Dis wardrobe vector type about between what 
networks the equipment in which cryptocommunication is possible is arranged to which link, and 
cryptocommunication can be performed, if it is the routing protocol of a link state type, it will include 
which router exists in the distance vector into path formation information. And in case encryption data 
are transmitted, it enables it to perform easily newly generating, if there is no corresponding key using 
the key corresponding to the data encryption equipment of a reception place. 
In addition, use and generation of a key can use the technique generally used from the former. 
[0023] 

The above-mentioned cryptocommunication approach can be enforced by the cryptocommunication 
system constituted as shown in drawing 1 . 

Including the network configuration components of two or more routers LI 1 which intervene between 
communication device [ of the transmitting side allotted on alpha network ] Tl 1, communication device 
[ of the receiving side allotted on beta network ] T12, and these communication devices, i.e., A router, D 
router L12, B router L13, and C router L14, and others, this cryptocommunication system 1 is 
constituted so that communication link for Takayoshi and cryptocommunication can be realized to 
coincidence. 

It shall connect through a wide area network [ like the Internet ] whose alpha network and beta network 

are. 

[0024] 

Each routers LI 1-L14 are a kind of computers which have memory and CPU, and have the function of 
the routing protocol formed by reading the program code with which the CPU was recorded on the 
predetermined record medium, and performing, the function of cryptocommunication, and the function 
to make these functions cooperate. Although CPUs are cover-half record media, such as semiconductor 
memory in which a readout is possible, when mounted in a router, the record medium which recorded 
this program code circulates through portability record media, such as CD-ROM, and may be installed 
in the above-mentioned cover-half record medium at the time of mounting. 

About the function of a routing protocol, although it is fundamentally [ as the thing of the conventional 
router ] the same, it differs from the function with which the router conventional at the point of having 
made it make the functions of cryptocommunication including the following two information 
cooperating to the path formation information exchanged for other routers by the routing protocol is 
equipped. 

(1) Arrangement and Interface ID of the node (router) which can perform cryptocommunication 
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Example: "A router is in A node whose cryptocommunication is possible" 

(2) The communication path ID which the node makes the object of cryptocommunication 

implementation * 

Example: "the object (communication path ID) of the cryptocommunication in A router receives the 
communication link of alpha network and gamma network" 

The format of the data corresponding to such information becomes what was doubled with the adapted 
network protocol or the routing protocol. For example, in the case of OSPF of IP network, the 
information will be included in LSA (Link State Advertisement) mentioned later. 
[0025] 

On the other hand, about the function of cryptocommunication, as each router is the following, it 
performs cryptocommunication. 

(1) To the communication link corresponding to the communication path ID for cryptocommunication 
implementation, encipher commo data, for example, a packet, and generate encryption data. 
Example: As for the packet to which the source address of the packet which passes A router belongs to 
gamma network, and the destination address belongs to beta network, it is ****(ed) and used for the key 
for the codes "which it lets be the objects of cryptocommunication since the destination address suits a 
communication path ID (2)" when the thing of a node with the communication path ID corresponding to 
a communication path is held beforehand. When the key is not held, it is performing key generation 
between the node (router), and a key is secured. 

Example: "the router in which cryptocommunication called B router is possible existed on the path 
addressed to beta network from A router, and A router knows by the routing protocol that the B router is 
considering as the object of cryptocommunication implementation to beta network. Then, the packet set 
as the object of cryptocommunication is enciphered using the key corresponding to B router." 
About the function to which both function is made to link, it mentions later. 
[0026] 

In addition, although it is desirable for all the routers LI 1-L14 to have as for the above function, the 
operation which has enciphered the packet sent from the communication device Tl 1, and is relayed and 
which is this invention even if it is the case where only the router which acts mainly has, either is 
possible. 
[0027] 

Next, the communication configuration by the cryptocommunication system 1 of this operation gestalt is 
explained. Here, the communication device Tl 1 in alpha network and the network address between the 
A routers LI 1 like illustration "163.135.10.0/24", The interface address between the communication 
device T12 in beta network, the B router L13, or the C router L14 "163.135.20.0/24", The interface 
address of the A router LI 1 " 163. 135. 100. 10", The interface address of the B router L13 
"163.135.200.20", The example in the case of improving the above OSPF which the network address of 
the C router L14 shall be "163.135.300.30", and is the representation of a link state type routing 
protocol, and performing cryptocommunication is given. OSPF is indicated by the specifications 
RFC2328, RFC1 131, and STD0054 published in the international organization IETF at the detail. 
[0028] 

The example of a format of the router link LSA which each routers LI 1-L14 transmit among the path 
formation information used by OSPF, i.e., a link condition advertising packet, (LSA:Link State 
Advertisement) is shown in drawing 2 . 

This router link LSA is various link informations received and passed between proximal routers, and 
consists of a link condition header and a LSA section. Using the information which a router type, Link 
ID, link data, etc. are described by the LSA section, and is described by this, each router can recognize 
the information about arrangement of other routers, and can use now for path computation or a re- 
calculation. Drawing 3 shows the router type contents and the example of the Link ID and link data to it. 
Types 1-4 are information which the existing router possesses, and Type 5 Is the part added with this' 
operation gestalt, i.e., the information relevant to cryptocommunication. By this type 5 of description, 
which router understands where cryptocommunication is performed. In Type 5, when link data are Null, 



http://www4.ipdl.ncipi.gojp/cgi-bin/tran_web_cgi_ejje 



10/25/2006 



JP,3821990,B [DETAILED DESCRIPTION] 



Page 7 of 8 



it is shown that somewhere which is not determined yet and cryptocommunication can be performed. 
[0029] 

LSA can send two or more link informations which it can have with each routers LI 1 -LI 4. Therefore, if 
one router is performing cryptocommunication among two or more routers, two or more LSA(s) for 
cryptocommunication can also be specified. For example, it is shown that the router which has as the 
address "163. 135. 100. 10" which transmitted this LSA by LSA of Type 5 if Link ID is "163.135.100.10" 
and link data are "163.135.20.0/24" is in the condition which can perform a phase hand with the address 
of "163. 135.20.0/24" and cryptocommunication. Furthermore, it is the same to Link ID, and if there is 
LSA of link data "163.135.30.0/24", it is shown that a router "163.135.100.10" is in the condition whose 
cryptocommunication is possible also with "163.135.30.0/24" of phase hands. 
[0030] 

Such amelioration OSPF is used, and when enciphering a packet and transmitting, each routers LI 1-L14 
will declare the information on the cryptocommunication point by LSA. The information on 
cryptocommunication origin is also included in this declaration. Each routers LI 1-L14 record the 
information on the network on the own database of a router as "a cryptocommunication charge network 
(or host)", when a decryption of the packet which goes to a certain network can be performed again. 
This information turns into information required in order to perform key generation between that LSA 
transmitting former routers, when each router receives the cryptocommunication LSA of other routers 
and it has the same "cryptocommunication charge network" as that cryptocommunication point. 
[0031] 

Routers are delivering the Hello packet (a thing like a keep alive signal to a contiguity router), 
respectively, and self LSA gets across to the other party by the link-Bayh-link between the routers in 
which this delivery is possible, respectively. For example, when the B router L13 and the C router L14 
are routers in which encryption and a decryption are possible, that that and it are operating normally gets 
across to the A router LI 1 through the D router L12. The A router LI 1 gets to know that it is ready for 
the router L13 to perform self "cryptocommunication charge network" and cryptocommunication by 
LSA of the B router LI 3, and carries out the process which generates the key for codes between the B 
routers L13. This process may be a process of key generation of generally being used. The A router LI 1 
carries out the process which generates a key also between the C routers L14 again. 
[0032] 

Drawing 4 (a) is drawing having shown the contents of the link table (former information on routing 
table) of the A router LI 1 when usually converging in a path. In the example of illustration, the A router 
LI 1 is linked with alpha network and the D router LI 2, and cryptocommunication charge networks are 
alpha and gamma. The B router L13 and the C router L14 are linked with beta network and the D router 
L12, and both "cryptocommunication charge networks" is beta. Or it links D router with the A router 
LI 1, the B router L13, and the C router L14 and it does not have assignment of a "cryptocommunication 
charge network", it is somewhere which is not yet determined. In addition, the "cryptocommunication 
charge network" does not necessarily need to adjoin. 
[0033] 

This link table to the A router LI 1 forms the optimal path to Network beta from Network alpha like an 
alpha network (communication device Tl 1) ->A router LI 1 ->D router L12 ->B router L13 ->beta 
network (communication device T12). 
[0034] 

On the other hand, the A router LI 1 cooperates with the link table of drawing 4 (a), and sets up an 
encryption filter like drawing 5 (a). That is, the "cryptocommunication charge network" of the A router 
LI 1 is an alpha network, and the router which makes beta a "cryptocommunication charge network" on 
a path is the B router L13. Then, the A router LI 1 generates Key a between the B routers L13 (it is **** 
(ed) when Key a is already held). The semantics of this link table is "the sending agency address's 
(network's) being alpha, and the transmission place address's (network's) enciphering the packei (alpha- 
>beta) of beta with Key a, and transmitting to the B router LI 3 (set peer (B)). M Thereby, the 
cryptocommunication using Key a becomes possible. 
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[0035] 

Here, the case where a failure occurs in the B router LI 3 is considered. 

In this case, since LSA which the B router L13 emits does not reach the D router L12 and the A router 
LI 1, the A router LI 1 recovers a path as what cannot use the B router LI 3 using the function of a 
routing protocol. Drawing 4 (b) is drawing having shown the contents after renewal of the link table 
(origin of routing table) of the A router LI 1 when converging in a recovery path. Like illustration, the 
link information of the B router LI 3 is lost. Although an optimal path is changed from this link table 
like an alpha network (communication device Tl 1) ->A router LI 1 ->D router L12 ->C router L14 - 
>beta network (communication device T12), the key a which cooperates with path modification and the 
A router LI 1 uses further is made to change into Key c dynamically with this operation gestalt. 
[0036] 

That is, if the link table of drawing 4 (b) is updated, the A router LI 1 will cooperate to this, and will 
update the contents of the encryption filter like drawing 5 (b). That is, since, as for the router which 
makes beta a "cryptocommunication charge network" on a path, it turns out that it is the C router L14, 
the A router LI 1 generates Key c between the C routers L14 (it is ****(ed) when Key c is already held). 
The semantics of this link table is "the sending agency address's (network's) being alpha, and the 
transmission place address's (network's) enciphering the packet (alpha->beta) of beta with Key c, and 
transmitting to the C router L14 (set peer (B))." 
[0037] 

Thus, since a setup of an encryption filter like drawing 5 (b) is obtained from the link table by the 
routing protocol after updating and modification of the key accompanying path modification is made 
even if a failure occurs in the B router L13 and path modification is made, cryptocommunication can be 
continued. 
[0038] 
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TECHNICAL PROBLEM 



[Problem(s) to be Solved by the Invention] 

Usually, also when a failure occurs in an optimal path, an alternate route can be formed in the midst 
which is performing not only a communication link but cryptocommunication using the above- 
mentioned function and above-mentioned backup routing function of a routing protocol. However, since 
the function of a routing protocol or the change function to a backup path, and the function of 
cryptocommunication have another composition, with the existing structure, in the case of 
cryptocommunication, the enciphered IP packet (encryption data) cannot be decrypted, and it may be 
unable to continue cryptocommunication. This is explained below. 
[0009] 

Here, a communication device Tl 1 is connected to the configuration N12 shown in drawing 7 , i.e., a 
router, through data encryption equipment M21, a communication device T22 is connected to a router 
N15, and IP network configuration by which data encryption equipment M22 and M23 was connected to 
juxtaposition between the router N12 and the router N15, respectively is assumed further. 
[0010] 

Each routers N12 and N15 and data encryption equipment M21 and M22 exchange the path formation 
information which it has mutually, suit, and form the optimal path between networks. The optimal path 
in always [ forward ], i.e., the path at the time of usually converging in a path, is the communication 
device Tl 1 -> data-encryption-equipment M21 -> router N12 -> data-encryption-equipment M22 -> 
router N15 -> communication device T12, and data encryption equipment M21 enciphers the packet 
transmitted from a communication device T22 using the key (for example, the key A) used between self- 
equipment and data encryption equipment M22. 
[0011] 

Suppose that a certain failure occurred with data encryption equipment M22, a path change was made by 
the function of a routing protocol, and the optimal path was automatically changed into the 
communication device Tl 1 -> data-encryption-equipment M21 -> router N 12 -> data-encryption- 
equipment M23 -> router N15 -> communication device T12 in this condition. In this case, the key (for 
example, the key B) used between data encryption equipment M21 and data encryption equipment M23 
differs from the key A mentioned above. However, in data encryption equipment M21, since there is no 
modification in the transmission place (communication device T 12) of a packet, from the conventional 
routing protocol, it cannot recognize that the key for codes of the data transmitted to a communication 
device T12 from a communication device Tl 1 should be changed into Key B from Key A. Therefore, 
since it will be enciphered with Key A with data encryption equipment M21 and the packet concerned 
cannot decode this in the data encryption equipment M23 using Key B, cryptocommunication is 
unrecoverable after all. 
[0012] 

The tunnel mode which enciphers collectively a part for the data division of IP header which includes 
the address of a transmission place in cryptocommunication, and a packet (namely, payload), and 
communicates by attaching IP header including the address of a new transmission place (decryption 
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equipment), Although the transmission place address has the transport mode which does not encipher 
but enciphers only a part for the data division of a packet, when a failure occurs with data encryption 
equipment M22 as mentioned above, with data encryption equipment M21, the need for modification of 
a key can be recognized in neither of the modes. 
[0013] 

Such a problem is produced in common, the case where a router, data encryption equipment, a 
communication device, etc. are newly extended by the part (node) which was an optimal path till then, 
when the parts of a router etc. move, and not only when a path failure occurs during 
cryptocommunication but when. It originates in having been [ this ] fixed, and the key used for 
cryptocommunication having been fixed. [ of arrangement of the router in this conventional kind of 
communication link for Takayoshi etc. ] 
[0014] 

Then, even if this invention is the case where modification arises in the arrangement configuration of the 
equipment with which the communication link for Takayoshi and cryptocommunication perform 
encryption and a decryption in a network realizable to coincidence, it makes it a main technical problem 
to offer the technique which changes the key for codes dynamically and enables it to continue 
cryptocommunication safely. 
[0015] 

[Translation done.] 
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MEANS 



[Means for Solving the Problem] 

The record medium which becomes suitable when a computer realizes the cryptocommunication 
approach by which this invention was improved in the above-mentioned technical problem for the 
solution reason, a cryptocommunication system, communication link repeating installation, and 
communication link repeating installation is offered. 
[0016] 

The cryptocommunication approach of this invention is an approach of performing communication link 
for Takayoshi, and cryptocommunication through a network realizable to coincidence. The optimal path 
on a network is formed by exchanging mutually predetermined path formation information including the 
arrangement information about arrangement of the communication link repeating installation in which 
cryptocommunication is possible among two or more communication link repeating installation, and 
suiting on a network. While performing cryptocommunication of commo data between the 
communication link repeating installation which exists in this optimal path It is characterized by 
continuing said cryptocommunication using the key fixed mutually between the communication link 
repeating installation which updates said path formation information, carries out the reconstititution of 
the new optimal path when the configuration of the communication link repeating installation on said 
network is changed, and consists in the optimal path by which the reconstititution was carried out and in 
which cryptocommunication is possible. Each communication link repeating installation records the 
identification information of the communication device or a network, when a decryption of the 
enciphered commo data which goes to a certain communication device or network can be performed, 
and when path formation information is received from other communication link repeating installation 
and the cryptocommunication point holds the same identification information as said identification 
information, it is made to settle between communication link repeating installation besides the above on 
a key. 
[0017] 

The cryptocommunication system of this invention is a cryptocommunication system which performs 
cryptocommunication of commo data between the communication link repeating installation which 
forms the optimal path on the network which can realize communication link for Takayoshi, and 
cryptocommunication to coincidence, and exists in this optimal path by exchanging predetermined path 
formation information mutually among two or more communication link repeating installation, and 
suiting. The path formation information on each communication link repeating installation is what 
includes the arrangement information about arrangement of the communication link repeating 
installation in which cryptocommunication is possible on said network. At least one of two or more of 
the communication link repeating installation It is constituted so that the arrangement information after 
the modification concerned may be notified to other communication link repeating installation, when it 
detects that the arrangement configuration of the communication link repeating installation on the 
optimal path under cryptocommunication was changed. Other one [ at least ] While updating the path 
formation information on self based on said notice and carrying out the reconstititution of the new 
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optimal path to it, it is characterized by being constituted so that said cryptocommunication may be 
continued using the key fixed mutually between the communication link repeating installation which 
consists in the optimal path by which the reconstititution was carried out< and in which 
cryptocommunication is possible. 
[0018] 

In the communication link repeating installation which performs cryptocommunication among other 
communication link repeating installation which exists in this optimal path while the communication 
link repeating installation of this invention forms the optimal path of the commo data on a network 
based on predetermined path formation information Said path formation information is a thing including 
the arrangement information about arrangement of the communication link repeating installation in 
which cryptocommunication is possible. A means to update the contents of said arrangement 
information included in the path formation information on self when other communication link repeating 
installation which serves as a communications partner during cryptocommunication becomes 
communication link impossible, It is equipment characterized by continuing cryptocommunication using 
the key which was equipped with a means to form a new optimal path based on the path formation 
information after updating, and a means to detect other communication link repeating installation in 
which the cryptocommunication on the newly formed optimal path is possible, and was fixed between 
the detected communication link repeating installation concerned. 
[0019] 

it is the information more specifically mutually delivered and carried out among other communication 
link repeating installation based on a predetermined routing protocol, and, as for path formation 
information, the information about arrangement of the node which can perform cryptocommunication, 
and its node fix said key based on this identification information including the identification information 
of the communication path made into the object of cryptocommunication implementation. When the key 
fixed between nodes with identification information is held beforehand, the key is ****(ed), and when 
the key is not held, said key is secured by performing key generation between the nodes concerned. 
[0020] 

The updating means in communication link repeating installation deletes the arrangement information 
about it, when the communication link repeating installation used as communication link impossible is 
during cryptocommunication, when there is communication link repeating installation extended during 
cryptocommunication, it adds the arrangement information about it, and when there is communication 
link repeating installation moved during cryptocommunication, it corrects the arrangement information 
about it. 
[0021] 

The record medium which this invention offers based on predetermined path formation information 
including the arrangement information about arrangement of the communication link repeating 
installation in which cryptocommunication is possible The function which forms the optimal path on the 
network which can realize communication link for Takayoshi, and cryptocommunication to coincidence, 
When the function to perform cryptocommunication between communications-partner equipment, and 
the configuration of said communications-partner equipment are changed, while updating the contents of 
said arrangement information included in the path formation information on self and forming a new 
optimal path based on the path formation information after updating It is the record medium with which 
the program code for forming on a computer the function which continues cryptocommunication using 
the key fixed among other communications-partner equipments which exist in this new optimal path was 
recorded and in which a computer readout is possible. 
[0022] 

[Embodiment of the Invention] 

Hereafter, the operation gestalt of this invention is explained with reference to a drawing. 
When the communication link for Takayoshi and cryptocommunication are performing 
cryptocommunication between the equipment which delivers path formation information in a network 
realizable to coincidence according to a routing protocol, the information about arrangement of the 
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equipment in which cryptocommunication is possible is included in the above-mentioned path formation 

information, and it is made to make path formation information and the information about modification 

of a key link in this invention. < 

For example, if it is the routing protocol of the De Dis wardrobe vector type about between what 

networks the equipment in which cryptocommunication is possible is arranged to which link, and 

cryptocommunication can be performed, if it is the routing protocol of a link state type, it will include 

which router exists in the distance vector into path formation information. And in case encryption data 

are transmitted, it enables it to perform easily newly generating, if there is no corresponding key using 

the key corresponding to the data encryption equipment of a reception place. 

In addition, use and generation of a key can use the technique generally used from the former 

[0023] 

The above-mentioned cryptocommunication approach can be enforced by the cryptocommunication 
system constituted as shown in drawing 1 . 

Including the network configuration components of two or more routers LI 1 which intervene between 
communication device [ of the transmitting side allotted on alpha network ] Tl 1, communication device 
[ of the receiving side allotted on beta network ] T12, and these communication devices, i.e., A router, D 
router L12, B router L13, and C router L14, and others, this cryptocommunication system 1 is 
constituted so that communication link for Takayoshi and cryptocommunication can be realized to 
coincidence. 

It shall connect through a wide area network [ like the Internet ] whose alpha network and beta network 

are. 

[0024] 

Each routers LI 1-L14 are a kind of computers which have memory and CPU, and have the function of 
the routing protocol formed by reading the program code with which the CPU was recorded on the 
predetermined record medium, and performing, the function of cryptocommunication, and the function 
to make these functions cooperate. Although CPUs are cover-half record media, such as semiconductor 
memory in which a readout is possible, when mounted in a router, the record medium which recorded 
this program code circulates through portability record media, such as CD-ROM, and may be installed 
in the above-mentioned cover-half record medium at the time of mounting. 

About the function of a routing protocol, although it is fundamentally [ as the thing of the conventional 
router ] the same, it differs from the function with which the router conventional at the point of having 
made it make the functions of cryptccommunication including the following two information 
cooperating to the path formation information exchanged for other routers by the routing protocol is 
equipped. 

(1) Arrangement and Interface ID of the node (router) which can perform cryptocommunication 
Example: "A router is in A node whose cryptocommunication is possible" 

(2) The communication path ID which the node makes the object of cryptocommunication 
implementation 

Example: "the object (communication path ID) of the cryptocommunication in A router receives the 
communication link of alpha network and gamma network" 

The format of the data corresponding to such information becomes what was doubled with the adapted 
network protocol or the routing protocol. For example, in the case of OSPF of IP network, the 
information will be included in LS A (Link State Advertisement) mentioned later 
[0025] 

On the other hand, about the function of cryptocommunication, as each router is the following, it 
performs cryptocommunication. 

(1) To the communication link corresponding to the communication path ID for cryptocommunication 
.implementation, encipher commo data, for example, a packet, and generate encryption data. 
Example: As for the packet to which the source address of the packet which passes A router belongs to 
gamma network, and the destination address belongs to beta network, it is ****( e d) and used for the key 
for the codes "which it lets be the objects of cryptocommunication since the destination address suits a 
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communication path ID (2)" when the thing of a node with the communication path ID corresponding to 

a communication path is held beforehand. When the key is not held, it is performing key generation 

between the node (router), and a key is secured. < 

Example: "the router in which cryptocommunication called B router is possible existed on the path 

addressed to beta network from A router, and A router knows by the routing protocol that the B router is 

considering as the object of cryptocommunication implementation to beta network. Then, the packet set 

as the object of cryptocommunication is enciphered using the key corresponding to B router." 

About the function to which both function is made to link, it mentions later. 

[0026] 

In addition, although it is desirable for all the routers LI 1-L14 to have as for the above function, the 
operation which has enciphered the packet sent from the communication device Tl 1, and is relayed and 
which is this invention even if it is the case where only the router which acts mainly has, either is 
possible. 
[0027] 

Next, the communication configuration by the cryptocommunication system 1 of this operation gestalt is 
explained. Here, the communication device Tl 1 in alpha network and the network address between the 
A routers Lll like illustration "163.135.10.0/24", The interface address between the communication 
device T12 in beta network, the B router L13, or the C router L14 "163.135.20.0/24", The interface 
address of the A router LI 1 " 163. 135. 100. 10", The interface address of the B router L13 
"163.135.200.20", The example in the case of improving the above OSPF which the network address of 
the C router L14 shall be " 163. 135.300.30", and is the representation of a link state type routing 
protocol, and performing cryptocommunication is given. OSPF is indicated by the specifications 
RFC2328, RFC1 131, and STD0054 published in the international organization IETF at the detail 
[0028] 

The example of a format of the router link LSA which each routers LI 1-L14 transmit among the path 
formation information used by OSPF, i.e., a link condition advertising packet, (LSA:Link State 
Advertisement) is shown in drawing 2 . 

This router link LSA is various link informations received and passed between proximal routers, and 
consists of a link condition header and a LSA section. Using the information which a router type, Link 
ID, link data, etc. are described by the LSA section, and is described by this, each router can recognize 
the information about arrangement of other routers, and can use now for path computation or a re- 
calculation. Drawing 3 shows the router type contents and the example of the Link ID and link data to it. 
Types 1-4 arc information which the existing router possesses, and Type 5 is the part added with this 
operation gestalt, i.e., the information relevant to cryptocommunication. By this type 5 of description, 
which router understands where cryptocommunication is performed. In Type 5, when link data are Null, 
it is shown that somewhere which is not determined yet and cryptocommunication can be performed 
[0029] 

LSA can send two or more link informations which it can have with each routers LI 1-L14. Therefore, if 
one router is performing cryptocommunication among two or more routers, two or more LS A(s) for 
cryptocommunication can also be specified. For example, it is shown that the router which has as the 
address "163.135.100.10" which transmitted this LSA by LSA of Type 5 if Link ID is "163.135.100.10" 
and link data are "163.135.20.0/24" is in the condition which can perform a phase hand with the address 
of " 163. 135.20.0/24" and cryptocommunication. Furthermore, it is the same to Link ID, and if there is 
LSA of link data "163.135.30.0/24", it is shown that a router "163.135.100.10" is in the condition whose 
cryptocommunication is possible also with "163.135.30.0/24" of phase hands. 
[0030] 

Such amelioration OSPF is used, and when enciphering a packet and transmitting, each routers LI 1-L14 
will declare the information on the cryptocommunication point by LSA. The information on 
cryptocommunication origin is also included in this declaration. Each routers LI 1-L14 record the 
information on the network on the own database of a router as "a cryptocommunication charge network 
(or host)", when a decryption of the packet which goes to a certain network can be performed again. 



http://www4.ipdl.ncipi.go.jp/cgi-bin/tran_web_cgi_ejje 10/25/2006 



JP,382 19903 [MEANS] 



Page 5 of 7 



This information turns into information required in order to perform key generation between that LSA 
transmitting former routers, when each router receives the cryptocommunication LSA of other routers 
and it has the same "cryptocommunication charge network" as that cryptocommunication point, 
[0031] 

Routers are delivering the Hello packet (a thing like a keep alive signal to a contiguity router), 
respectively, and self LSA gets across to the other party by the link-Bayh-link between the routers in 
which this delivery is possible, respectively. For example, when the B router L13 and the C router L14 
are routers in which encryption and a decryption are possible, that that and it are operating normally gets 
across to the A router LI 1 through the D router LI 2. The A router LI 1 gets to know that it is ready for 
the router LI 3 to perform self "cryptocommunication charge network" and cryptocommunication by 
LSA of the B router LI 3, and carries out the process which generates the key for codes between the B 
routers LI 3. This process may be a process of key generation of generally being used. The A router LI 1 
carries out the process which generates a key also between the C routers L14 again. 
[0032] 

Drawing 4 (a) is drawing having shown the contents of the link table (former information on routing 
table) of the A router LI 1 when usually converging in a path. In the example of illustration, the A router 
LI 1 is linked with alpha network and the D router LI 2, and cryptocommunication charge networks are 
alpha and gamma. The B router L13 and the C router L14 are linked with beta network and the D router 
LI 2, and both "cryptocommunication charge networks" is beta. Or it links D router with the A router 
LI 1, the B router L13, and the C router L14 and it does not have assignment of a "cryptocommunication 
charge network", it is somewhere which is not yet determined. In addition, the "cryptocommunication 
charge network" does not necessarily need to adjoin. 
[0033] 

This link table to the A router LI 1 forms the optimal path to Network beta from Network alpha like an 
alpha network (communication device Tl 1) ->A router LI 1 ->D router L12 ->B router L13 ->beta 
network (communication device T12). 
[0034] 

On the other hand, the A router LI 1 cooperates with the link table of drawing 4 (a), and sets up an 
encryption filter like drawing 5 (a). That is, the "cryptocommunication charge network" of the A router 
LI 1 is an alpha network, and the router which makes beta a "cryptocommunication charge network" on 
a path is the B router LI 3. Then, the A router LI 1 generates Key a between the B routers L13 (it is **** 
(ed) when Key a is already held). The semantics of this link table is "the sending agency address's 
(network's) being alpha, and the transmission place address's (network's) enciphering the packet (alpha- 
>beta) of beta with Key a, and transmitting to the B router L13 (set peer (B))." Thereby, the 
cryptocommunication using Key a becomes possible. 
[0035] 

Here, the case where a failure occurs in the B router L13 is considered. 

In this case, since LSA which the B router L13 emits does not reach the D router L12 and the A router 
LI 1, the A router LI 1 recovers a path as what cannot use the B router L13 using the function of a 
routing protocol. Drawing 4 (b) is drawing having shown the contents after renewal of the link table 
(origin of routing table) of the A router LI 1 when converging in a recovery path. Like illustration, the 
link information of the B router L13 is lost. Although an optimal path is changed from this link table 
like an alpha network (communication device Tl 1) ->A router LI 1 ->D router L12 ->C router L14 - 
>beta network (communication device T12), the key a which cooperates with path modification and the 
A router LI 1 uses further is made to change into Key c dynamically with this operation gestalt. 
[0036] 

That is, if the link table of drawing 4 (b) is updated, the A router LI 1 will cooperate to this, and will 
update the contents of the encryption filter like drawing 5 (b). That is, since, as for the router which 
makes beta a "cryptocommunication charge network'^on a path, it turns out that it is the C router L14, 
the A router LI 1 generates Key c between the C routers L14 (it is ****(ed) when Key c is already held). 
The semantics of this link table is "the sending agency address's (network's) being alpha, and the 
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transmission place address's (network's) enciphering the packet (alpha->beta) of beta with Key c, and 
transmitting to the C router L14 (set peer (B)). M 

[0037] , 
Thus, since a setup of an encryption filter like drawing 5 (b) is obtained from the link table by the 
routing protocol after updating and modification of the key accompanying path modification is made 
even if a failure occurs in the B router LI 3 and path modification is made, cryptocommunication can be 
continued. 
[0038] 

In addition, although it assumed that modification arose in the arrangement configuration of the router in 
which cryptocommunication is possible, and the path failure by failure of a router etc. arose as an 
example in case the key used by this is changed with this operation gestalt This invention can be 
similarly applied, not only an example such but when the key to be used is changed, as a result of 
extending a router for example, on a network or moving a router to other networks from a certain 
network. That is, it is possible to continue cryptocommunication by delivering path formation 
information mutually using the function of a routing protocol, updating the arrangement information 
with each router, and forming an optimal path automatically, without setting up cryptocommunication 
by hand control. Moreover, the router concerned becomes possible [ also finding out the phase hand 
equipment which performs cryptocommunication automatically ] only by specifying the target network 
thru/or target host who performs cryptocommunication as the path formation information on a router. 
These functions are functions adapted to the actual communication configuration that the number of the 
routers connected on a certain network fluctuates continuously, and correspondence becomes possible 
easily by this also at the spread of mobile mold communication links. 
[0039] 

Although the router was mentioned as the example and this operation gestalt explained it as 
communication link repeating installation, the structure of this invention can be applied to the equipment 
at large which is in case the phase hand of cryptocommunication changes. Moreover, although it is a 
desirable gestalt to prepare the function to deliver path formation information to other equipments and 
mutual like this operation gestalt, and the function to make the key for codes change dynamically, in one 
equipment (for example, router), it is not having to make it such [ always ] a gestalt. For example, it 
does not become trouble to constitute so that the communication device connected to the router may 
have the function to change the key for codes dynamically based on the notice from a router, when 
enforcing the cryptocommunication approach of this invention. 
[0040] 

although this operation gestalt explained the example which made IP network communication media, if 
this invention is the network which can realize communication link for Takayoshi, and 
cryptocommunication to coincidence, since it is applicable irrespective of the scale - ANSE - use with 
the intranet and extranet which are a cure network is also possible. 
[0041] 

Since the mutual delivery function of path formation information like a routing protocol becomes 
application of this invention with a premise, Although it will use within the closed network which does 
not use the ISP when using other original routing protocols or using ISP (Intarnet Service Provider) 
which cannot perform interconnect of a routing protocol Even if it is the case where the ISP is used, use 
in the network beyond a closed network is also possible by relaying path formation information by the 
approach by service of ISP with a well-known tunneling technique. 
[0042] 

It can respond also to a network configuration change which are effective especially when it is changed 
frequently logically, and is called a mobile network physically [ this invention / the 
cryptocommunication point ] flexibly. 
[0043] 

Application in the cryptocommunication commercial scene for consumer (one gestalt of use of the 
network service for an individual) is also possible for this invention again. The mainstream of the 
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cryptocommunication technique for current and an individual is SSL (Secure Socket Layer). This aims 
at performing cryptocommunication of end to end by enciphering by the communicative upper layer, 
and the terminal (communication device) itself which an individual operates enciphering commo date, 
and transmitting. It can become an effective means to make this invention apply to the network which 
the terminal (a mobile mold terminal is included) which this individual operates accesses, when 
promoting the above-mentioned network service. 
[0044] 



[Translation done.] 
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* NOTICES * 

JPO and NCIPI are not responsible for any , 
damages caused by the use of this translation. 

1. This document has been translated by computer. So the translation may not reflect the original 
precisely. 

2. **** shows the word which can not be translated. 
3 Jn the drawings, any words are not translated. 

DESCRIPTION OF DRAWINGS 
[Brief Description of the Drawings] 

[Drawing 1] The cryptocommunication structure-of-a-system Fig. which applied this invention. 
rPrawing 2] Drawing having shown the example of a format of the router link LS A. 
[Drawing 3] Drawing having shown the type class of router link LS A. 

[Drawing 4] For (a), (b) is the contents explanatory view of the link table used when forming the 
optimal path at the time of using a routing protocol, and the contents explanatory view of the link table 
updated at the time of failure generating. 

[Drawing 5] For (a), (b) is drawing having shown the contents of a setting of the encryption filter at the 
time of normal actuation, and drawing having shown the contents of a setting of the encryption filter 
updated at the time of failure generating. 

rPrawing 6] The network configuration Fig. for using for the explanation of the optimal-path restoration 
at the time of using a routing protocol in the former. 

IDrawing 7] It is a network configuration Fig. for using for explanation of the optimal-path restoration at 

the time of using the routing protocol and cryptocommunication in the former. 

[Description of Notations] 

1 Cryptocommunication System 

Tl 1, T12 Communication device 

L11-L14,N11-N15 Router 

M21-M23 Data encryption equipment 

[Translation done.] 
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